Executive brief
node-latex-pdf is a software library used to convert LaTeX documents into PDF files. A security flaw in this library allows an attacker to execute unauthorized commands on the server hosting the application. This could lead to a complete system takeover, theft of sensitive data, or disruption of business operations.
Technical details
A command injection vulnerability (CWE-77) exists in all versions of the node-latex-pdf npm package. The vulnerability stems from improper neutralization of special elements used in a command when processing LaTeX files for PDF conversion. An attacker can exploit this by providing malicious input that is subsequently executed by the underlying system shell. This requires no authentication and can be triggered remotely if the application exposes the PDF conversion functionality to user-supplied data. As of the latest advisory, there is no known patch available for this package.
Affected products
- toolbuddy node-latex-pdf All versions up to 0.0.2
Timeline
- 2020-12-10: disclosed: Initial discovery/reporting by Snyk
- 2022-08-02: advisory: NVD published the CVE record
- 2022-08-03: advisory: GitHub Advisory Database published GHSA-32fw-9wq8-9x9c